← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Bigpanda Notifier
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controlle...Show more
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.
1Haystacksoftware
1Arq Backup
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
1Suse
1Rancher
Jun 17, 2026
Sep 7, 2022
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been s...Show more
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13.Show less
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potential...Show more
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
1Hcltech
1Versionvault Express
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL VersionVault Express exposes administrator credentials.
3Debian
OpenstackRedhat
4Debian Linux
Openshift Container PlatformOpenstack Platform+1 more
Jun 17, 2026
Aug 29, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
1Theforeman
1Foreman
Jun 17, 2026
Aug 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data con...Show more
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Postgresql
1Postgresql
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authenticati...Show more
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering dat...Show more
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
1Jenkins
1Collabnet
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller f...Show more
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Git
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
1Fiserv
1Prologue
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would...Show more
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.Show less
1Redhat
1Keycloak
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threa...Show more
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.Show less
1Intel
2Active Management Technology Firmware
Standard Manageability
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
1Intel
2Active Management Technology Firmware
Standard Manageability
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
1Intel
1Datacenter Group Event
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
1Intel
1Team Blue
Jun 17, 2026
Aug 18, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.